2026년 1월 APT 공격 동향 보고서(국내)

2026-02-19 Ahnlab January 2026 APT Attack Trends Report (Domestic)

https://asec.ahnlab.com/ko/92647/

Thumbnail for 2026년 1월 APT 공격 동향 보고서(국내)

AhnLab's January 2026 domestic APT trends report says spear phishing dominated observed attacks against Korean targets, with LNK files representing the largest share of activity. One LNK chain runs PowerShell to reach external URLs, copies curl.exe under alternate names, downloads a legitimate AutoIt program and malicious AutoIt script, and registers scheduled tasks for persistence. Another LNK chain uses Windows curl.exe to download and execute HTA files from GitHub repositories or Google Drive, then drops downloaders that load an infostealer, keylogger, and backdoor in memory. The reported capabilities include command execution, directory listing, file upload, file download, system information theft, keylogging, and collection of virtual-asset-related information, making the activity relevant for Korean defenders monitoring malicious attachments and post-compromise tooling.

Related Reports

« Back